zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 7, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 7, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • European Commission Moves to Strengthen Cybersecurity of the Space Sector
  • Multiple Critical Vulnerabilities Revealed in Supermicro's BMC Firmware
  • “Operation Jacana” Reveals DinodasRAT Custom Backdoor
  • Data broker / initial-access broker / hacktivist group: XSS user p3rf and XSS user Jettix
  • Vulnerabilities: CVE-2023-44488 and CVE-2023-43269
  • Exploits: CVE-2022-21881
  • Breaches: Combolist: 'x80 Chatgpt.txt' and BreachForums: xpdel.com Breach

European Commission Moves to Strengthen Cybersecurity of the Space Sector

The European Commission, backed by the European Union Agency for the Space Programme (EUSPA), has launched a call for interest in establishing an EU Space Information Sharing and Analysis Centre (ISAC). Aligned with the EU Space Strategy for Security and Defence (announced in March 2023), the goal is to enhance the security and resilience of the EU space sector. It will facilitate information exchange among members, including Mid-Caps, SMEs, startups, and major industrial groups, while encouraging relevant public entities to participate. The call remains open until October 31, 2025.

Multiple Critical Vulnerabilities Revealed in Supermicro's BMC Firmware

Several security vulnerabilities have been disclosed in Supermicro's baseboard management controllers (BMCs) Intelligent Platform Management Interface (IPMI) firmware. These vulnerabilities, designated as CVE-2023-40284 through CVE-2023-40290, range in severity from High to Critical. They allow unauthenticated attackers to gain root access to the BMC system. Supermicro has issued a BMC firmware update to address these vulnerabilities. BMCs specialized processors facilitate remote management and remain operational even when the host OS is offline, making them attractive for persistent malware deployment.

“Operation Jacana” Reveals DinodasRAT Custom Backdoor

A new malware threat known as "DinodasRAT'' has been employed against a government entity in Guyana. The malware has been linked to a targeted espionage campaign called "Operation Jacana,” with suspected ties to Chinese state-sponsored hackers. The campaign initiated with spear-phishing emails related to Guyanese public affairs. Intruders, once inside, navigated the network laterally. DinodasRAT was employed for file exfiltration, Windows registry manipulation, and command execution. Researchers noted the use of a Vietnamese government website to serve malware, indicating a sophisticated operation.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • RXSS user p3rf: Claims to be selling network access to 8 separate companies worldwide.
  • XSS user Jettix):: Claims to be selling VPN access to an undisclosed cleaning products manufacturer.

VULNERABILITIES

  • CVE-2023-44488:: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
  • CVE-2023-43269:: pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

EXPLOITS

BREACHES

Tags: DIB, tlp:green